Courseiva
Malware, Social Engineering and Network AttacksmediumMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

An employee receives a text message claiming to be from the company's IT department, stating that their account will be suspended unless they click a link to verify their credentials. Which type of social engineering attack is this?

⚠ Common exam trap

Candidates often confuse SMiShing with generic phishing because both involve a link and credential theft, but the CEH exam specifically distinguishes them by the delivery medium — SMS versus email.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SMiShing

SMiShing (SMS phishing) is the correct classification because the attack vector is a text message (SMS) rather than email or voice. The message impersonates the IT department and uses a link to harvest credentials, which is the hallmark of SMiShing — phishing conducted via Short Message Service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vishing

    Why it's wrong here

    Vishing, a portmanteau of "voice" and "phishing," is a social engineering attack conducted exclusively over telephone calls. Attackers manipulate victims into divulging sensitive information or performing actions by impersonating trusted entities, often using Caller ID spoofing to enhance credibility and urgency. Since the question explicitly states the employee received a "text message," vishing is an incorrect classification for this scenario, as it relies exclusively on audio communication.

  • Phishing

    Why it's wrong here

    Phishing is a broad social engineering technique where attackers attempt to acquire sensitive information, such as usernames, passwords, and credit card details, by masquerading as a trustworthy entity in an electronic communication. While it primarily refers to email-based attacks, the term can encompass other digital mediums. However, for attacks specifically leveraging SMS text messages, a more precise and distinct term exists, making "phishing" too general for this particular scenario.

  • Baiting

    Why it's wrong here

    Baiting is a social engineering attack that exploits human curiosity or greed by offering something enticing, often in a physical form. This typically involves leaving malware-infected physical devices, such as USB drives or CDs, in public places, hoping a victim will pick them up and insert them into their computer. Since the scenario describes a digital text message rather than a physical lure designed to be physically interacted with, baiting is an inappropriate classification for this specific type of attack.

  • SMiShing

    Why this is correct

    SMiShing is a specialized form of phishing that utilizes Short Message Service (SMS) text messages to deceive individuals. Attackers send fraudulent text messages, often containing malicious links or requests for personal information, by impersonating legitimate organizations like banks, government agencies, or delivery services. Given that the employee received a "text message" claiming to be from a specific entity, SMiShing precisely describes this attack vector.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.